Close Menu
NCIJ Network NCIJ Network
    What's Hot

    River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

    August 3, 2026

    Strategy Sells $105M in Bitcoin as Dollar Reserve Hits $4B

    August 3, 2026

    ‘Cheating’ birds change their tune

    August 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
    • Strategy Sells $105M in Bitcoin as Dollar Reserve Hits $4B
    • ‘Cheating’ birds change their tune
    • How Will Europe Defend Itself Against Russian Missiles?
    • French court rejects pro-Kremlin commentator’s expulsion appeal
    • Burnham’s ‘Manchesterism’ got him to No 10 – but will it work for the UK?
    • Author of Democrats’ 2024 Autopsy Says Party Left Out Key Chapter
    • Best Robot Lawn Mowers (2026): My Picks After 3 Years of Testing
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 3, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 03, 2026Mobile Security / Vulnerability

    An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.

    Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit.

    “The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe,” Censys researcher Aidan Holland said in an analysis published on July 31, 2026.

    DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.

    The kit, which specifically targets iOS versions 18.4 through 18.7, has been observed to employ watering holes as a starting point to trigger now-patched vulnerabilities in Apple’s mobile operating system to execute JavaScript that ultimately facilitates the deployment of GHOSTBLADE, an information-stealing malware.

    Cybersecurity

    The use of DarkSword has since expanded in scope following a public leak of its source code, prompting other threat actors to join the exploitation bandwagon.

    The latest findings from Censys show that the login page for a panel called “DarkSword Admin” matches seven hosts across three countries as of July 30, 2026, in addition to a Singapore-based host (“38.181.52[.]95”) running three distinct exploit-panel front ends and a Hong Kong host that bundles an Apple ID credential-harvesting decoy (“103.106.190[.]217”).

    One such login panel served on the IP address “38.22.89[.]117:8888” contains Chinese-language field labels for “username,” “password,” and “Log in.” The other six IP addresses are below –

    • 103.97.128[.]67:8888
    • 162.4.136[.]30:8888
    • 223.26.63[.]56:8888
    • 151.243.126[.]191:8888
    • 107.175.49[.]181:3000
    • 103.238.129[.]112:3000

    The attack flow is fairly consistent in that it begins when a victim reaches one of the operator’s domains – an AWS-console impersonation subdomain or an Apple ID sign-in page – causing a malicious iframe element to load JavaScript that fires the DarkSword chain and finally deploys GHOSTBLADE modules.

    On successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules and commences the file-exfiltration sweep. The harvested data is then packaged and transmitted to attacker-controlled endpoints. The attacker then logs in to one of the panels, namely DarkSword Admin, Decode Dashboard, or C2 Control Panel, to extract the pilfered data.

    The IP addresses associated with the two other login panels are as follows –

    • 103.226.155[.]200 (Decode Dashboard)
    • 103.226.155[.]201 (Decode Dashboard)
    • 202.8.120[.]249 (Decode Dashboard)
    • 103.106.190[.]217 (C2 Control Panel), which also co-hosts the Apple ID decoy sign-in page

    “This cluster runs the leaked kit rather than a reimplementation, and the evidence is a shared staging-page hash plus Russian-language code comments carried over from the leaked source,” Holland said.

    Cybersecurity

    What’s more, the Singaporean host (now no longer active) has been found to host an administration panel for Coruna, another iOS exploit kit that predates DarkSword and goes after iOS versions 3.0 through 17.2.1. There is some evidence to suggest that a threat actor known as UNC6353 has leveraged both exploit kits in its attacks aimed at Ukrainian targets.

    Censys said it also discovered an open directory listing in Frankfurt (“93.152.221[.]37”) that exposes the operator’s tooling, including an SSH key comment “jkcing@apt,” a web-content fuzzer, and references to a previously undocumented malware family referred to as Thorn C2.”

    “The ‘C2 Control Panel’ login itself is a visually distinct build from the other two panels: a near-black #06060d background, a #ff0050 red accent, an animated particle-canvas effect, a group name rendered directly on the page (亚太集团, ‘Asia-Pacific Group’), and a visible Telegram contact link, hxxps://t[.]me/YATA0000,” it noted. “That’s the first direct contact channel we’ve recovered for this operator; the other panels give us a login gate and nothing else.”

    actor Chinese DarkSword Deploy GHOSTBLADE iOS kit Leaked threat
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

    Brinks Home Discloses Data Breach as Hackers Leak Files

    Stop depending on heroics and start operationalizing third-party risk

    Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

    The right hates The Odyssey because of its ‘wokeness’ – but it missed an even bigger threat to its worldview | Peter Swallow

    OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

    August 3, 2026

    Strategy Sells $105M in Bitcoin as Dollar Reserve Hits $4B

    August 3, 2026

    ‘Cheating’ birds change their tune

    August 3, 2026

    How Will Europe Defend Itself Against Russian Missiles?

    August 3, 2026
    Latest Posts

    Oil has harmed the nature and people of the Niger Delta; human rights may save it

    July 23, 2026

    Drought announcement looms for parts of Wales over river levels

    July 23, 2026

    Swiss Bank BancaStato Launches Bitcoin Trading Through Sygnum And Avaloq

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

    August 3, 2026

    Strategy Sells $105M in Bitcoin as Dollar Reserve Hits $4B

    August 3, 2026

    ‘Cheating’ birds change their tune

    August 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.